Nmap is a widely used open-source network reconnaissance and auditing tool, with a minimal but prominent vulnerability footprint centered on the core scanner and its packet-capture library, Npcap. The recurring weakness classes in its disclosures include memory-safety issues such as double-free conditions and path-traversal flaws in file handling, reflecting the low-level networking and system-interaction demands of a scanning engine. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nmap over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58058MEDIUM Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffe | Jun 28, 2026 | 6.5 | 32 | NO | NO |
CVE-2013-4885MEDIUM The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted Ful | Oct 26, 2013 | 6.8 | 29 | NO | YES |
CVE-2018-15173HIGH Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service. | Aug 8, 2018 | 7.5 | 27 | NO | NO |
CVE-2017-18594HIGH nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.ns | Aug 29, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-11490HIGH An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendqueue_queue() or pcap_sendqueue_transmit() results in kernel | Apr 24, 2019 | 7.8 | 25 | NO | NO |
CVE-2018-1000161MEDIUM nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite | Apr 18, 2018 | 5.7 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nmap.
Media articles that mention a CVE ID that affects a product developed by Nmap — matched by CVE ID, not by vendor name.